Malicious PDF — malware analysis report

Static analysis result for SHA-256 58963a64b19f5b89…

MALICIOUS

PDF

38.2 KB Created: 2020-09-18 04:36:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2026-05-07
MD5: 0348851e541bad56e8b85dbd00424d73 SHA-1: ecade308f3a379bca7a7b273b67e6277a5aa098b SHA-256: 58963a64b19f5b89404b33a465d669b8dc5c61e7a41ceb8caa7395ffd3a34fdb
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high density of external links, many of which point to redirector infrastructure. The primary malicious URL identified is https://ttraff.me/wix?keyword=super+mario+maker+3ds+rom, which is likely used to direct users to further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARM
    Small PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=super+mario+maker+3ds+rom In PDF document text
    • http://files.rootedandrestored.org/uploads/1/3/1/8/131871416/6ab6af876.pdfIn PDF document text
    • http://files.enviroleblanc.com/uploads/1/3/1/3/131381518/6985609.pdfIn PDF document text
    • http://metifadol.marinashacola.com/uploads/1/3/2/8/132816202/finedowasobugafax.pdfIn PDF document text
    • http://talojuwow.littleannadesigns.com/uploads/1/3/1/6/131636772/tatarelu_xovaz_lakuvorivu_bekuwasarum.pdfIn PDF document text
    • http://files.cloudcatmedia.com/uploads/1/3/1/4/131437222/9868216.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://fee0bd53-e364-4064-9c77-4eed96379755.filesusr.com/ugd/89363e_64e1622c13fa4bf2b9957e0e4d66fef7.pdf?index=trueIn PDF document text
    • https://4524d377-4397-41b4-9ebe-b6b4d8ce5d0f.filesusr.com/ugd/c5d40f_98d7270746f2457387817b1e170dba9e.pdf?index=trueIn PDF document text
    • https://e1253266-ff06-49d6-8db4-c35f377df742.filesusr.com/ugd/7ab50f_20128c3aeb1742d799213eee463e314f.pdf?index=trueIn PDF document text
    • https://dce2ef38-6231-4c72-96df-fa1f0bf82676.filesusr.com/ugd/98e2de_ff286fbdbd9448838d28d11fca775151.pdf?index=trueIn PDF document text
    • https://69e43390-8f31-4700-ae62-fb50172d45f7.filesusr.com/ugd/21e9e0_8b191f730c234480a8045ea46cb0155c.pdf?index=trueIn PDF document text
    • https://2d71682f-d2ae-4002-b42f-11585e70ab08.filesusr.com/ugd/d2759c_192874e227cf43b59c5fd5a3e95855db.pdf?index=trueIn PDF document text
    • https://697fb011-5326-43ca-832b-4e8795fc08f9.filesusr.com/ugd/f241d9_c0867e2807e348a8b0956bfe2c33ae34.pdf?index=trueIn PDF document text
    • https://fd52cdbb-6f9d-485f-986f-413a04abded7.filesusr.com/ugd/e73fea_87e4c7a24f3b48fa959ea67448b37244.pdf?index=trueIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000563f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x563F 5404 bytes
SHA-256: 537130d88354150ddeb86106d4bc62b8f67f8a97311b2c6887cbd28b2cb08a95
font_01_sfnt_off00006886.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6886 10512 bytes
SHA-256: a3a65509519ef7939100e13000c39451a8089ae34a443a587eacc67991e90f53